figma-swiftui

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external Figma designs and user-provided SwiftUI source files, creating a surface for indirect instructions to influence agent behavior.
  • Ingestion points: Processes data from Figma file keys and node IDs through the get_design_context tool, as well as the contents of local .swift files.
  • Boundary markers: The instructions provide explicit guidance to treat structural references (like React+Tailwind output) as metadata rather than literal source code, and emphasize using screenshots as the visual source of truth.
  • Capability inventory: The skill has the ability to write SwiftUI code to the local filesystem and execute JavaScript scripts within the Figma environment using the use_figma tool.
  • Sanitization: It implements strict semantic mapping rules (e.g., iOS HIG token mapping) and requires environment verification, such as checking for available fonts in Figma before performing operations.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates and executes JavaScript code to manipulate the Figma canvas based on the interpretation of SwiftUI source code.
  • Evidence: The references/code-to-design.md file contains detailed instructions for assembling use_figma scripts that call Figma API functions like figma.createAutoLayout() and figma.createText().
  • Context: This dynamic execution is the primary mechanism for the skill's code-to-design functionality and uses provided utility helpers for asset and symbol handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — figma-swiftui